Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-Other
Total 27865 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0886 1 Microsoft 2 Internet Information Server, Internet Information Services 2018-10-30 7.5 HIGH N/A
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.
CVE-2000-0951 1 Microsoft 1 Internet Information Services 2018-10-30 5.0 MEDIUM N/A
A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.
CVE-2000-0970 1 Microsoft 2 Internet Information Server, Internet Information Services 2018-10-30 7.5 HIGH N/A
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
CVE-2000-1027 1 Cisco 1 Pix Firewall Software 2018-10-30 5.0 MEDIUM N/A
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established.
CVE-1999-1585 1 Sun 1 Sunos 2018-10-30 7.2 HIGH N/A
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.
CVE-2000-1104 1 Microsoft 2 Internet Information Server, Internet Information Services 2018-10-30 7.5 HIGH N/A
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.
CVE-1999-0806 1 Sun 1 Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in Solaris dtprintinfo program.
CVE-1999-0410 1 Sun 1 Sunos 2018-10-30 7.2 HIGH N/A
The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.
CVE-2001-0269 1 Sun 1 Sunos 2018-10-30 10.0 HIGH N/A
pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.
CVE-2001-0403 1 Sun 1 Sunos 2018-10-30 7.2 HIGH N/A
/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.
CVE-2001-0421 1 Sun 2 Solaris, Sunos 2018-10-30 6.4 MEDIUM N/A
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
CVE-2001-0470 1 Sun 1 Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.
CVE-1999-1550 1 F5 1 Tmos 2018-10-30 5.0 MEDIUM N/A
bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.
CVE-2001-0096 1 Microsoft 2 Internet Information Server, Internet Information Services 2018-10-30 5.0 MEDIUM N/A
FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.
CVE-1999-1587 1 Sun 2 Solaris, Sunos 2018-10-30 2.1 LOW N/A
/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.
CVE-2001-0095 1 Sun 1 Sunos 2018-10-30 1.2 LOW N/A
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.
CVE-1999-0211 1 Sun 1 Sunos 2018-10-30 5.0 MEDIUM N/A
Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.
CVE-1999-0212 1 Sun 1 Sunos 2018-10-30 7.8 HIGH N/A
Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.
CVE-2000-0071 1 Microsoft 2 Internet Information Server, Internet Information Services 2018-10-30 5.0 MEDIUM N/A
IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.
CVE-2001-0151 1 Microsoft 1 Internet Information Services 2018-10-30 5.0 MEDIUM N/A
IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.